Rezultaty skanu uzupełniającego Farbar Recovery Scan Tool (x86) Wersja:18-04-2016 Uruchomiony przez pawel (2016-04-20 13:35:43) Uruchomiony z C:\Users\pawel\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2013-10-18 11:35:53) Tryb startu: Normal ========================================================== ==================== Konta użytkowników: ============================= Administrator (S-1-5-21-2484601583-1567469604-3372653222-500 - Administrator - Disabled) Gość (S-1-5-21-2484601583-1567469604-3372653222-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2484601583-1567469604-3372653222-1002 - Limited - Enabled) pawel (S-1-5-21-2484601583-1567469604-3372653222-1001 - Administrator - Enabled) => C:\Users\pawel ==================== Centrum zabezpieczeń ======================== (Załączenie wejścia w fixlist spowoduje jego usunięcie.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Zainstalowane programy ====================== (W fixlist dozwolone tylko załączanie programów adware z flagą "Hidden" w celu ich uwidocznienia. Programy adware powinny zostać w poprawny sposób odinstalowane.) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Acrobat Reader DC - Polish (HKLM\...\{AC76BA86-7AD7-1045-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated) Adobe Flash Player 21 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 21.0.0.182 - Adobe Systems Incorporated) Age of Empires III - The WarChiefs (HKLM\...\InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III - The WarChiefs (Version: 1.00.0000 - Microsoft Game Studios) Hidden Age of Empires III (HKLM\...\InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}) (Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (Version: 1.00.0000 - Microsoft Game Studios) Hidden Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.16.282 - Avira Operations GmbH & Co. KG) Avira Launcher (HKLM\...\{74d1ef14-dd39-4749-b051-e183a1e27f5e}) (Version: 1.1.58.35540 - Avira Operations GmbH & Co. KG) Avira Launcher (Version: 1.1.58.35540 - Avira Operations GmbH & Co. KG) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform) Detektor Winampa (HKU\S-1-5-21-2484601583-1567469604-3372653222-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Dropbox (HKU\S-1-5-21-2484601583-1567469604-3372653222-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.) EVEREST Home Edition v2.20 (HKLM\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) Faraon (HKLM\...\Pharaoh) (Version: - ) Football Manager 2011 (HKLM\...\Football Manager 2011) (Version: 11.0.0.0 - Sports Interactive) GTA2 (HKLM\...\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}) (Version: 1.00.001 - ) Medieval II Total War (HKLM\...\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}) (Version: 1.02.001 - SEGA) MGI PhotoSuite 8.06 (Remove Only) (HKLM\...\MGI_PHOTOSUITE_V806) (Version: - ) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM\...\{90110415-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NVIDIA nView 136.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 136.53 - NVIDIA Corporation) NVIDIA Sterownik graficzny 309.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 309.00 - NVIDIA Corporation) Opera Stable 36.0.2130.65 (HKLM\...\Opera 36.0.2130.65) (Version: 36.0.2130.65 - Opera Software) Panel sterowania NVIDIA 309.00 (Version: 309.00 - NVIDIA Corporation) Hidden PrimaPAGE 98 (HKLM\...\PrimaPAGE 98) (Version: - ) Primax Colorado 600p/1200p (CD required) (HKLM\...\Colorado 600p/1200p) (Version: - ) Safari (HKLM\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation) Skype™ 7.21 (HKLM\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.) Starcraft (HKLM\...\Starcraft) (Version: - ) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve) Stronghold 2 Deluxe (HKLM\...\{417FE195-C31B-4A41-A057-E7404188B32E}) (Version: 1.00.000 - ) Stronghold Crusader HD (HKLM\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.30.0003 - Firefly Studios) UsbFix (HKLM\...\Usbfix) (Version: 7.162 - El Desaparecido - www.usbfix.net - www.sosvirus.net) VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) Winamp (HKLM\...\Winamp) (Version: 5.65 - Nullsoft, Inc) WinRAR 5.10 (32-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) ==================== Niestandardowe rejestracje CLSID (filtrowane): ========================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{E7A37920-253C-4FF1-B169-298A7CE6CAA9}\localserver32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\pawel\AppData\Roaming\Dropbox\bin\DropboxExt.30.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2484601583-1567469604-3372653222-1001_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\pawel\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) ==================== Zaplanowane zadania (filtrowane) ============= (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) Task: {17B90842-97A2-4CD7-A5FE-6D809FA04E0F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {1AA86CBD-3D43-4FCD-847B-57C4A4849BD0} - System32\Tasks\e-pity2015_styczen => C:\Program Files\e-file\e-pity2014\Assets\signxml.exe [2015-04-07] (e-file sp. z o.o.) Task: {25B352A9-3372-4259-9AF0-A3B52924F36F} - System32\Tasks\{3D66F622-E3F0-4C2D-8A91-08F2FF28FF67} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{417FE195-C31B-4A41-A057-E7404188B32E}\setup.exe" -d "C:\Program Files\InstallShield Installation Information\{417FE195-C31B-4A41-A057-E7404188B32E}" Task: {2F7ED56D-2995-4358-8CD7-00B35E4A00B2} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2484601583-1567469604-3372653222-1001Core => C:\Users\pawel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16] (Dropbox, Inc.) Task: {39F1EFD0-6771-41C1-BE53-CE49C33C694F} - System32\Tasks\{0ACEEB39-2BE5-4EF9-A6D4-F89D843CE2C9} => C:\Program Files\Firefly Studios\Stronghold 2 Deluxe\Stronghold2.exe [2007-05-18] () Task: {3BD1145A-EB35-46B9-BDB2-4AC8C62D545A} - System32\Tasks\e-pity2015_kwiecien => C:\Program Files\e-file\e-pity2014\Assets\signxml.exe [2015-04-07] (e-file sp. z o.o.) Task: {4236C02F-5B53-4A96-ADE3-03FF866566EF} - System32\Tasks\{E538F833-CDF6-4A92-A421-51AD370FC311} => C:\Program Files\Firefly Studios\Stronghold 2 Deluxe\Stronghold2.exe [2007-05-18] () Task: {493D17D8-D3F0-4B4E-81CE-DC874D1267CE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2484601583-1567469604-3372653222-1001UA => C:\Users\pawel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16] (Dropbox, Inc.) Task: {72C8F055-9297-479C-AA62-16610B9755D2} - System32\Tasks\EOKS => C:\Users\pawel\AppData\Roaming\EOKS.exe <==== UWAGA Task: {7EAB1C22-AEB4-450C-9984-45E208230972} - System32\Tasks\{F8106563-ACC5-484C-BEDC-812278378AF3} => C:\Program Files\Firefly Studios\Stronghold 2 Deluxe\Stronghold2.exe [2007-05-18] () Task: {9D1CF2A5-2B8D-4FDF-93E5-9899A48F92E7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_21_0_0_182_pepper.exe [2016-03-12] (Adobe Systems Incorporated) Task: {A1AC8DD7-D3F3-4215-BDE5-34034E18CAAC} - System32\Tasks\{CF372588-1CE9-4FC6-9170-69C662E1F3DD} => D:\moha\moha\MOHAA.exe Task: {C8EB142B-BEA1-4B3F-98F2-BF0D2EDD8C70} - System32\Tasks\Opera scheduled Autoupdate 1455736816 => C:\Program Files\Opera nowa\launcher.exe [2016-04-11] (Opera Software) Task: {CBEE7B95-6441-4A24-B4E9-6D3AE658A537} - System32\Tasks\{9C270152-6A00-482F-AEB9-7CE9D3ABD386} => C:\Program Files\Firefly Studios\Stronghold 2 Deluxe\Stronghold2.exe [2007-05-18] () Task: {CED23BDF-057A-4EDD-94A2-A900CFB723CE} - System32\Tasks\{BA2834DE-6AD2-4214-A1BC-8D846567A6F6} => pcalua.exe -a "C:\Program Files\Lavalys\EVEREST Home Edition\everest.exe" -d C:\Users\pawel\Desktop Task: {D7028E25-856E-41DF-B872-7600D610C09B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {DA5961BA-7170-441A-B94B-2BE6008DDBA0} - System32\Tasks\{6396B5E5-F104-4EBD-A683-8242C94DD944} => pcalua.exe -a C:\Users\pawel\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=smt <==== UWAGA Task: {DDFA3080-6F2A-418C-AAB0-1D29B8F9B4BC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd) Task: {EB5E9810-BC08-4DA9-855C-3A1B87F060D3} - System32\Tasks\EXEK => C:\Users\pawel\AppData\Roaming\EXEK.exe <==== UWAGA Task: {EFEEC0DA-E531-4B57-A88D-6F1F655438B2} - System32\Tasks\{9670E2C5-8E69-482D-ADF6-1019216DE591} => D:\moha\moha\MOHAA.exe (Załączenie wejścia w fixlist spowoduje przesunięcie pliku zadania (.job). Plik uruchamiany docelowo przez zadanie nie zostanie przeniesiony.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\system32\Macromed\Flash\FlashUtil32_21_0_0_182_pepper.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2484601583-1567469604-3372653222-1001Core.job => C:\Users\pawel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2484601583-1567469604-3372653222-1001UA.job => C:\Users\pawel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\EOKS.job => C:\Users\pawel\AppData\Roaming\EOKS.exe <==== UWAGA Task: C:\Windows\Tasks\EXEK.job => C:\Users\pawel\AppData\Roaming\EXEK.exe <==== UWAGA ==================== Skróty ============================= (Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.) ==================== Załadowane moduły (filtrowane) ============== 2014-05-02 16:21 - 2013-11-22 20:53 - 00357224 _____ () C:\Program Files\NVIDIA Corporation\nview\nvshell.dll 2015-12-11 15:38 - 2016-03-21 23:50 - 00034768 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2016-04-18 06:38 - 2016-03-21 23:51 - 00019408 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2016-04-18 06:38 - 2016-03-21 23:50 - 00116688 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2015-12-11 15:38 - 2016-03-21 23:50 - 00093640 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2015-12-11 15:38 - 2016-03-21 23:50 - 00018376 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\select.pyd 2015-12-11 15:38 - 2016-04-08 20:20 - 00019760 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00105928 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-04-18 06:38 - 2016-03-21 23:50 - 00392144 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2015-12-11 15:38 - 2016-04-08 20:20 - 00381752 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2015-12-11 15:38 - 2016-03-21 23:50 - 00692688 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00020816 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2015-12-11 15:38 - 2016-03-21 23:51 - 00112592 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 01682760 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00020808 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2015-12-11 15:38 - 2016-04-08 20:20 - 00021840 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00038696 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\fastpath.pyd 2016-04-18 06:38 - 2016-03-21 23:52 - 00020936 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00024528 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32event.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00114640 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32security.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00124880 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00021832 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00175560 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32gui.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00030160 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00043472 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32process.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00028616 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32ts.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00048592 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32service.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00026456 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00057808 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\win32profile.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00117056 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2015-12-11 15:38 - 2016-04-08 20:20 - 00023376 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2015-12-11 15:38 - 2016-03-21 23:50 - 00134608 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_elementtree.pyd 2016-04-18 06:38 - 2016-03-21 23:50 - 00134088 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2016-04-18 06:38 - 2016-03-21 23:51 - 00240584 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\jpegtran.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00024392 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2016-04-18 06:38 - 2016-03-21 23:52 - 00036296 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\librsync.dll 2016-04-18 06:38 - 2016-04-08 20:19 - 00052024 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00021824 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00019776 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00020280 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2015-12-11 15:38 - 2016-03-21 23:52 - 00350152 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2016-02-18 11:21 - 2016-04-08 20:20 - 00022352 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2016-04-18 06:38 - 2016-04-08 20:19 - 00084280 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2016-04-18 06:38 - 2016-04-08 20:20 - 01826096 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2015-12-11 15:38 - 2016-03-21 23:51 - 00083912 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\sip.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 03928880 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 01971504 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00531248 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00132912 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00223544 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00207672 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00158008 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00042808 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd 2016-04-18 06:38 - 2016-03-21 23:54 - 00017864 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\libEGL.dll 2016-04-18 06:38 - 2016-03-21 23:54 - 01631184 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-12-11 15:38 - 2016-04-08 20:20 - 00024904 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00546096 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2016-04-18 06:38 - 2016-04-08 20:20 - 00357680 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2015-10-17 11:12 - 2016-03-21 23:56 - 00697304 _____ () C:\Users\pawel\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll 2014-09-25 20:44 - 2014-09-25 20:44 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll ==================== Alternate Data Streams (filtrowane) ========= (Załączenie wejścia w fixlist spowoduje usunięcie strumienia ADS.) AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118] ==================== Tryb awaryjny (filtrowane) =================== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Wartość "AlternateShell" zostanie przywrócona.) ==================== EXE - Powiązania (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci.) ==================== Internet Explorer - Witryny zaufane i z ograniczeniami =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru.) ==================== Hosts - zawartość: ========================== (Użycie dyrektywy Hosts: w fixlist spowoduje reset pliku Hosts.) 2009-07-14 04:04 - 2015-10-28 19:54 - 00001050 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 static3.cdn.ubi.com 127.0.0.1 ubisoft-orbit.s3.amazonaws.com 127.0.0.1 onlineconfigservice.ubi.com 127.0.0.1 orbitservice.ubi.com 127.0.0.1 ubisoft-orbit-savegames.s3.amazonaws.com ==================== Inne obszary ============================ (Obecnie brak automatycznej naprawy dla tej sekcji.) HKU\S-1-5-21-2484601583-1567469604-3372653222-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\pawel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Zapora systemu Windows [funkcja włączona] ==================== MSCONFIG/TASK MANAGER - Wyłączone elementy == (Obecnie brak automatycznej naprawy dla tej sekcji.) MSCONFIG\startupfolder: C:^Users^pawel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup ==================== Reguły Zapory systemu Windows (filtrowane) =============== (Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.) FirewallRules: [{769D8840-6E01-4FC3-8C7D-1EF3F3DAD323}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{F684A8C6-E4AE-4F62-B468-9E95C7646719}] => (Allow) C:\Program Files\Winamp\winamp.exe FirewallRules: [{E85D9E38-3BBE-4985-A124-7DEFD6CAFC29}] => (Allow) C:\Program Files\Winamp\winamp.exe FirewallRules: [TCP Query User{AA4B9431-398A-47DC-AF96-5901058DE15D}G:\moha\moha\mohaa.exe] => (Allow) G:\moha\moha\mohaa.exe FirewallRules: [UDP Query User{ABA3DAB5-ACE0-4928-9429-CFCBE6C1524E}G:\moha\moha\mohaa.exe] => (Allow) G:\moha\moha\mohaa.exe FirewallRules: [{8F740BEA-94B4-4F97-BCE4-CC8697D1B73B}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{5DA6DC04-BC41-405A-8F22-8405A95D7487}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{D94547E4-8487-4ADE-9E62-9389F3686E96}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{AB795AC8-0160-4298-B119-30340410A0A7}C:\program files\starcraft\starcraft.exe] => (Allow) C:\program files\starcraft\starcraft.exe FirewallRules: [UDP Query User{52416CD2-3BCA-421B-8DDB-50623B3D3F0C}C:\program files\starcraft\starcraft.exe] => (Allow) C:\program files\starcraft\starcraft.exe FirewallRules: [{F04FCFD9-1B67-4E1F-BBF8-24896B052E5F}] => (Allow) C:\Users\pawel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{2E814043-70CD-4A9A-9667-CDD2ACE9DA41}] => (Allow) C:\Users\pawel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{C2EBCBA3-1E10-4094-9F3A-036922482530}] => (Allow) C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe FirewallRules: [{C0650D32-8D26-46AA-8055-93D92640D824}] => (Allow) C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe FirewallRules: [TCP Query User{6E3D151A-EC33-4F68-B52C-0C5BA424200A}C:\program files\microsoft games\age of empires iii\age3.exe] => (Allow) C:\program files\microsoft games\age of empires iii\age3.exe FirewallRules: [UDP Query User{FF52F18B-1B74-4E62-90CD-61CA6524420A}C:\program files\microsoft games\age of empires iii\age3.exe] => (Allow) C:\program files\microsoft games\age of empires iii\age3.exe FirewallRules: [{5B5FF2F9-92A1-4DFB-B295-E3C5A5AC0883}] => (Allow) C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe FirewallRules: [{4D3E99F2-FDC3-452A-AF2D-0F497CFD9772}] => (Allow) C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe ==================== Punkty Przywracania systemu ========================= 06-04-2016 12:39:48 Zaplanowany punkt kontrolny 13-04-2016 20:47:05 Zaplanowany punkt kontrolny 15-04-2016 15:44:20 Installed Microsoft Fix it 50195 15-04-2016 18:19:53 Instalator modułów systemu Windows ==================== Wadliwe urządzenia w Menedżerze urządzeń ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Błędy w Dzienniku zdarzeń: ========================= Dziennik Aplikacja: ================== Error: (04/20/2016 01:15:14 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2016 06:42:26 AM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: Wykonanie kopii zapasowej nie zostało zakończone z powodu błędu zapisu w lokalizacji kopii zapasowej D:\. Błąd: Nie można odnaleźć lokalizacji kopii zapasowej lub jest ona nieprawidłowa. Przejrzyj ustawienia kopii zapasowej i sprawdź lokalizację kopii zapasowej. (0x81000006). Error: (04/18/2016 06:33:08 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 06:01:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 04:28:07 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2016 03:17:41 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2016 07:30:03 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Program iexplore.exe w wersji 11.0.9600.18205 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: 668 Godzina rozpoczęcia: 01d195a9fc9a08d1 Godzina zakończenia: 156 Ścieżka aplikacji: C:\Program Files\Internet Explorer\iexplore.exe Identyfikator raportu: Error: (04/13/2016 05:50:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/12/2016 06:05:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/12/2016 09:08:29 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Dziennik System: ============= Error: (04/20/2016 01:16:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Usługa Protokół rozpoznawania nazw równorzędnych zależy od usługi Menedżer tożsamości sieci równorzędnej, której nie można uruchomić z powodu następującego błędu: %%1053 Error: (04/20/2016 01:16:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Usługa Grupowanie sieci równorzędnej zależy od usługi Menedżer tożsamości sieci równorzędnej, której nie można uruchomić z powodu następującego błędu: %%1053 Error: (04/20/2016 01:16:59 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Nie można uruchomić usługi Menedżer tożsamości sieci równorzędnej z powodu następującego błędu: %%1053 Error: (04/20/2016 01:16:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Menedżer tożsamości sieci równorzędnej. Error: (04/15/2016 04:25:48 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Usługa Windows Update nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error: (04/15/2016 03:42:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na odpowiedź transakcji z usługi LanmanServer. Error: (04/12/2016 12:05:30 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (04/05/2016 12:06:58 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Usługa Windows Update nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error: (04/04/2016 11:19:43 AM) (Source: Microsoft-Windows-Diagnostics-Networking) (EventID: 5300) (User: ZARZĄDZANIE NT) Description: Wystąpił błąd. Struktura diagnostyki sieci nie może zakończyć naprawczej fazy operacji. Wygenerowano raport błędów systemu Windows. [2147942487] Error: (04/04/2016 10:31:06 AM) (Source: volsnap) (EventID: 67) (User: ) Description: Nie można zainstalować tworzonej kopii w tle woluminu C:. ==================== Statystyki pamięci =========================== Procesor: AMD Athlon(tm) 64 Processor 3500+ Procent pamięci w użyciu: 33% Całkowita pamięć fizyczna: 3007.55 MB Dostępna pamięć fizyczna: 2009.33 MB Całkowita pamięć wirtualna: 6013.43 MB Dostępna pamięć wirtualna: 4724.02 MB ==================== Dyski ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:246.09 GB) NTFS Drive e: (KINGSTON) (Removable) (Total:14.44 GB) (Free:14.44 GB) FAT32 ==================== MBR & Tablica partycji ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6860F257) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 14.5 GB) (Disk ID: AB534449) Partition 1: (Active) - (Size=14.4 GB) - (Type=0C) ==================== Koniec Addition.txt ============================